← Back

CVE-2021-22938

nvd nist
Published: Aug 16, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.

Affected (13)

1 product
Connect Secure
1 product
Pulse Connect Secure
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Version 9.1
Version 9.1 r1.0
Version 9.1 r10.0
Version 9.1 r11.0
Version 9.1 r2.0
Version 9.1 r3.0
Version 9.1 r4.0
Version 9.1 r5.0
Version 9.1 r6.0
Version 9.1 r7.0
Version 9.1 r8.0
Version 9.1 r9.0
Before 9.1

Timeline

No history available yet.